[m365weekly] #201

M365 Newsletter title logo M365 Weekly Newsletter

Issue #201


☁️Productivity & Modern Workplace

Outlook Paste Text Shortcut: What Happened? The Ctrl + Shift + V Paste Special shortcut stopped working in Outlook classic for Windows due to uncoordinated changes in Word, which serves as Outlook’s email editor. Microsoft is now rolling out a fix after months of delay, likely due to resource prioritization toward the “new” Outlook.

How to Use Page Templates in Microsoft Loop. You can simplify creating pages in Loop by using the built-in template gallery. Microsoft offers pre-designed templates tailored to various business needs, like meeting notes or project tracking. These templates provide a structured starting point, which you can customize further.

Why Your Day Starts Before Your Inbox Does. Your morning routine shapes your entire day. Taking control of those first 30–90 minutes with intentional habits can help you avoid reactive chaos. Tools like Microsoft To-Do, Viva Insights, or Copilot can simplify this process, but consistency matters most.

[FEATURED STORY] The dark side of direct send: How attackers are sneaking into your Microsoft 365 mail

Source: How to Disable Direct Send Feature in Microsoft 365

The big picture. A phishing campaign exploits Exchange Online’s Direct Send feature to spoof internal Microsoft 365 emails without authentication, bypassing standard security controls. Attackers send fake voicemail alerts with malicious attachments, often from Ukrainian IPs. Microsoft’s new Reject Direct Send PowerShell setting blocks these unauthenticated emails tenant-wide, enhancing protection.

Why is it important? Direct Send’s lack of authentication makes it a prime target for attackers to impersonate trusted insiders, increasing phishing risks. Enabling Reject Direct Send stops these spoofed emails but may disrupt legitimate device-generated mail unless properly authenticated. Combined with strict SPF/DKIM/DMARC policies, user training, and MFA enforcement, this measure is crucial to securing Microsoft 365 environments against advanced phishing threats.


☁️Copilot & AI

Everyday Copilot example prompts for SMB. Microsoft 365 Copilot can simplify your small business operations by automating tasks and enhancing productivity. From drafting marketing content and client proposals to analyzing sales data and creating HR checklists, Copilot provides actionable AI-driven assistance.

When to use Microsoft 365 Copilot versus a dedicated agent. When deciding between Microsoft 365 Copilot, Researcher, or Analyst for SMBs, use Copilot for quick tasks like drafting emails or summarizing meetings. Opt for Researcher for in-depth, citation-backed research, and Analyst for data-heavy analysis like forecasting or modeling.


☁️Sysadmin Stuff

Solving the Endless MFA Loop in Azure Virtual Desktop — What Really Went Wrong. You might encounter an endless MFA loop in Teams and Outlook on domain-joined Azure Virtual Desktops due to DPAPI encryption failures when keys can’t back up to a domain controller. Fix this by adding a registry key to allow local key storage.

Be Careful with Retention Labels That Use Created Date. Retention policies in Microsoft 365 can unintentionally delete files still in use, especially if older labels rely on creation dates instead of last modified dates. To prevent this, replacing outdated labels with new ones that use modified dates is essential.

How to Block Access to OWA and Allow the New Outlook. To block OWA while allowing the new Outlook for Windows, Microsoft recommends using a Conditional Access Policy instead of CAS settings. Both OWAEnabled and OneWinNativeOutlookEnabled should remain $true to ensure proper functionality.


☁️Security & Data Governance

Getting Started with Risky Users in Microsoft 365. Microsoft uses trillions of daily signals to identify risky sign-ins and users in Microsoft 365. Risk severity levels (low, medium, high) are determined by deviations from normal user patterns and detection types like leaked credentials or impossible travel. To stay ahead, you should configure alerts, use Conditional Access policies like requiring managed devices, and consider automated tools for scalable protection against account compromise.

Lifecycle of a Microsoft 365 Business Premium Tenant After License Expiry. When a Microsoft 365 Business subscription expires, the tenant goes through three stages: Expired, Disabled, and Deleted (permanent data removal). Administrators can renew during the first two stages or back up data before deletion.

How Microsoft defends against indirect prompt injection attacks. Indirect prompt injection attacks exploit vulnerabilities in large language models (LLMs) by embedding deceptive instructions in untrusted inputs, potentially leading to data exfiltration or unintended actions. Microsoft’s defense strategy includes hardened prompts, detection tools like Prompt Shields, data governance, consent workflows, and cutting-edge research.


☁️Noteworthy (long)reads

Microsoft’s Top Engineers Earn Salaries of Over $400,000. Microsoft’s compensation strategy for engineers highlights the intense competition in the tech industry, especially for AI talent. Top engineers at Level 70 can earn over $4 million annually, including stock awards and bonuses. Meanwhile, rivals like Meta and Google are offering massive signing bonuses and acquiring startups to secure talent. The race for AI dominance combines financial incentives, reputation, and strategic recruitment.

Crowdstrike’s massive cyber outage 1-year later: lessons enterprises can learn to improve security. The CrowdStrike outage last year highlighted how even routine updates can disrupt global infrastructure. It led to $5.4 billion in losses and forced a shift in cybersecurity, emphasizing resilience, better vendor evaluation, and fail-safes.


DATES TO KEEP IN MIND

October 14, 2025 – Windows 10 (Home, Pro, Enterprise, Education, IoT Enterprise) end of support – source

October 14, 2025 – Office 2016, Office 2019, Exchange Server 2016, Exchange Server 2019 end of support – source

October 2026Retirement of Microsoft Publisher app which has been a part of Office Suite for years.

☁️Classifieds

The Sample. A whole new way of discovering exciting email newsletters. Sign up and you will get sample newsletters based on the interests that you’ve tagged.


☁️On a Less Serious Note


☁️ We value your feedback!

How much are you enjoying this issue? Please give us your feedback so we can improve.

If you have any suggestions, just reply and leave us your message.


☁️ Last but not least …

Here are a few things you can do if you enjoyed reading this newsletter:

Did someone forward this email? Sign up for the weekly newsletter here.